The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

DeadLock Ransomware Leverages Decentralized Infrastructure to Increase Operational Resilience

Aug 14, 2026, 2:56:45 PM / by The Hivemind

DEADLOCK2026Verticals Targeted: Information Technology, Mining, Transportation and Logistics, Manufacturing, Hospitality, Consumer Goods
Regions Targeted: Europe, Asia, North America, South America, Africa

Executive Summary

DeadLock ransomware is an emerging financially motivated operation that combines conventional double-extortion tactics with decentralized infrastructure designed to improve operational resilience. Rather than relying solely on traditional domains and centralized servers, DeadLock uses blockchain-backed services, the Session messaging network, and distributed file-hosting components to support victim communications and leak operations. The architecture complicates infrastructure disruption while the malware itself incorporates resource-aware encryption, extensive defense evasion, and selective targeting techniques that demonstrate the continued evolution of enterprise ransomware operations.

Key Takeaways

  • DeadLock combines traditional double-extortion with decentralized infrastructure to improve operational resilience.
  • Recovery operations leverage Polygon blockchain, Session messaging, and Wasabi object storage rather than relying solely on conventional web infrastructure.
  • Resource-aware encryption throttling helps maintain host responsiveness while accelerating encryption of large files.
  • Researchers observed deployments by multiple ransomware groups, suggesting the encryptor may be shared across affiliate ecosystems.

What is DeadLock?

DeadLock reflects a broader evolution within the ransomware ecosystem in which threat actors are improving not only malware capabilities but also the resilience of their supporting infrastructure. Rather than depending entirely on conventional web hosting and centralized command infrastructure that can often be seized or disrupted, DeadLock distributes portions of its negotiation, configuration, and leak ecosystem across decentralized technologies.

Microsoft observed the ransomware using Polygon smart contracts to distribute configuration information, Session's decentralized messaging network for victim communications, and Wasabi object storage to facilitate publication of stolen data. Collectively, these technologies reduce reliance on individual domains or hosting providers while allowing operators to modify portions of their infrastructure without rebuilding victim-facing components.

Operationally, DeadLock continues to employ familiar double-extortion tactics, encrypting victim systems while threatening publication of stolen information. Microsoft has observed the ransomware affecting organizations across information technology, mining, transportation and logistics, manufacturing, hospitality, consumer goods, and other industries spanning Europe, Asia, North America, South America, and Africa. More than half of the publicly listed victims are located in Europe.

Although decentralized infrastructure improves resilience against traditional takedown efforts, it does not eliminate operational dependencies. DeadLock's recovery ecosystem continues to require public Polygon RPC services, proxy infrastructure, distributed storage providers, and reachable Session nodes. Consequently, defenders should view this architecture as increasing operational flexibility rather than making the ecosystem immune to disruption.

Technical Analysis

The ransomware incorporates several techniques intended to maximize encryption efficiency while minimizing user awareness during execution.

Resource-aware Encryption

Unlike many ransomware families that aggressively consume system resources, DeadLock continuously monitors CPU and memory utilization before dispatching additional encryption work. Encryption activity slows when memory utilization exceeds approximately 29% or CPU utilization exceeds roughly 70%, allowing infected systems to remain comparatively responsive throughout the attack. The malware also performs intermittent partial encryption on larger files to significantly reduce encryption time while still rendering files unusable.

Defense Evasion

Prior to encryption, DeadLock attempts to disable or terminate numerous security products, backup services, virtualization components, remote administration software, and cloud synchronization utilities. It additionally clears Windows event logs through multiple mechanisms, disables future logging, empties the recycle bin, and ultimately deletes its own executable after encryption completes.

Target Selection

The malware performs language-based geofencing before execution and immediately exits when systems are configured for several CIS-associated languages as well as select Middle Eastern languages, behavior commonly observed among ransomware families believed to operate from those regions.

Current vs Historical Activity

DeadLock was first observed in July 2025 and has published more than 80 victim organizations on its data leak site. Microsoft has observed the ransomware being deployed by multiple groups, including an affiliate associated with the Lynx and INC ransomware ecosystems, suggesting the encryptor may be adopted across multiple financially motivated operations rather than remaining exclusive to a single actor.

Historically, ransomware groups have relied on conventional web infrastructure, Tor hidden services, and centralized negotiation portals. DeadLock demonstrates an incremental shift toward distributing critical components across decentralized technologies that are inherently more resistant to traditional infrastructure disruption. While the underlying extortion model remains consistent with previous ransomware operations, the supporting infrastructure represents a notable evolution in how operators maintain continuity during law enforcement or hosting-provider intervention.

Analyst Commentary

DeadLock highlights an emerging trend in ransomware development where operational resilience is becoming as important as encryption capability. Rather than introducing fundamentally new extortion techniques, the operators have modernized the supporting ecosystem by decentralizing configuration management, victim communications, and portions of their data leak infrastructure. This approach increases the effort required to disrupt campaigns while allowing operators to recover more quickly from infrastructure losses.

Organizations should expect additional ransomware developers to adopt similar architectural patterns over time, particularly as blockchain-based services, decentralized messaging platforms, and distributed storage providers become increasingly accessible. As a result, defenders may need to place greater emphasis on early intrusion detection, privilege management, lateral movement prevention, and rapid containment, since infrastructure-focused disruption alone may become less effective against future ransomware operations. PolySwarm's crowdsourced malware analysis platform enables defenders to rapidly analyze emerging ransomware samples, identify novel capabilities, and enrich detections with threat intelligence from multiple security engines, helping organizations respond more quickly to evolving ransomware operations.

IOCs

PolySwarm has a sample of DeadLock.

 

A1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4

 

Click here to view all samples of DeadLock in our PolySwarm portal.

Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.

Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.

 



Topics: Threat Bulletin, Ransomware, double extortion, Session messaging, ransomware-as-a-service, DeadLock ransomware, decentralized infrastructure, Polygon blockchain, Wasabi object storage

The Hivemind

Written by The Hivemind

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts